AUTO-UPDATED

FBI disrupts massive AI-powered phishing service using a million URLs

The FBI, in collaboration with Google and Black Lotus Labs, has dismantled Outsider Enterprise, a China-based phishing-as-a-service operation responsible for stealing 3.8 million credit card records.

Key Points

  • The operation utilized AI and distributed phishing kits to impersonate trusted brands via SMS messages sent through AT&T, T-Mobile, and Verizon.
  • Google identified over 9,000 fake websites and more than one million fraudulent URLs linked to the network since 2023.
  • Authorities seized administration servers, a Shopify storefront, and $100,000 in cryptocurrency as part of the broader Operation Riptide.
  • The FBI took control of a Telegram bot used by the threat actors to manage customers and distribute phishing tools.
  • Google has filed a civil lawsuit to disrupt the infrastructure and is advocating for bipartisan legislation like the Stop SCAMS Act.

Why it Matters

This takedown highlights the growing threat of AI-enabled phishing-as-a-service models that facilitate large-scale financial fraud against millions of consumers. The coordinated effort underscores the necessity of public-private partnerships between federal law enforcement and major technology firms to combat sophisticated, cross-border cybercrime.
BleepingComputer Published by Bill Toulas
Read original